Key Takeaways
Data We Collect
We collect account, billing, authentication, and service usage data needed to operate and secure the Services.
No Selling or Ad Tracking
We do not sell personal information and do not use advertising or cross-site behavioral tracking.
Rights and Deletion
Depending on your location, you can request access, correction, deletion, restriction, and portability at privacy@relevate.app.
This Privacy Policy explains how Relevate V.O.F., doing business as Relevate ("we", "us", "our"), collects, uses, and shares personal information when you use our services ("Services"), including when you visit our website at https://relevate.app or use our application.
If you have any questions about this policy or our data practices, you can contact us at privacy@relevate.app.
1. Who we are
We are the data controller for the personal information described in this Privacy Policy.
2. What information we collect
Account and profile data
We collect information you provide when creating an account, using the Services, or contacting support. This may include:
- Name
- Email address
- Account, organization, and authentication identifiers
- Messages you send us (for example support requests)
We do not intentionally collect special category personal data. Please do not include sensitive information in support messages unless explicitly requested by us for a specific support case.
Billing and transaction data
When you subscribe to our Services, payment information is provided directly to our third-party payment processor. We do not store full credit card numbers or card verification codes (CVC) on our servers. We may receive limited billing metadata (such as transaction status, billing contact details, and invoice identifiers).
Authentication data
If you sign in using a third-party authentication provider (such as GitHub or an enterprise identity provider), we receive limited information necessary to authenticate you, typically your name, email address, and provider-specific user identifier.
Please review your sign-in provider's privacy policy for details on how they process your information.
We do not receive or store passwords.
Usage, device, and log data
When you use our Services, we automatically collect certain technical information, including:
- IP address
- Session and device identifiers
- Browser, OS, and device characteristics
- Authentication and security events
- Log and usage data such as timestamps, visited routes, sign-in events, workspace actions, and error events
- Language and regional preferences
This information is used solely for security, abuse prevention, account integrity, troubleshooting, reliability, and service operation.
We currently rely on first-party operational logs and do not use third-party advertising trackers or cross-site behavioral analytics.
We do not collect precise geolocation data (such as GPS location). IP addresses may be processed for security and fraud-prevention purposes.
3. How we use your information
We use personal information for the following purposes:
- To create and manage user accounts
- To authenticate users and provide access to the Services
- To deliver and operate the Services
- To process billing and subscription operations
- To communicate with users about their account or service-related matters
- To respond to inquiries and provide support
- To maintain the security and integrity of our Services
- To detect, prevent, and investigate fraud or misuse
- To comply with legal obligations and enforce our terms
We do not use personal information for advertising, marketing, profiling, or cross-site tracking.
AI and machine learning
- We do not use customer content or personal data to train our own machine learning models.
- If we use third-party AI providers to provide optional features, we only share the minimum necessary data and do not allow those providers to use your data for their own model training where such controls are available.
4. Legal bases for processing (EEA / UK)
If you are located in the European Economic Area or the United Kingdom, we process personal information on the legal bases below.
| Purpose | Data categories | Legal basis | Legitimate interest |
|---|---|---|---|
| Account creation and access | Account and authentication data | Performance of a contract | Not applicable |
| Service delivery and support | Account, usage, and support data | Performance of a contract | Not applicable |
| Security and fraud prevention | Usage, device, and log data | Legitimate interests | Keeping the Services secure and preventing misuse and fraud |
| Billing, invoices, and taxes | Billing and transaction data | Performance of a contract and legal obligations | Not applicable |
| Compliance and legal response | Relevant records by case | Legal obligations | Not applicable |
Where required, we will obtain your consent, and you may withdraw it at any time through account settings (where available) or by contacting privacy@relevate.app.
7. Subprocessors
We use trusted service providers to operate the Services.
| Category | Typical location | Purpose |
|---|---|---|
| Hosting and infrastructure providers | EU, U.S., and Canada (by deployment region) | Application hosting, storage, and reliability |
| Payment processors | U.S. and/or EU, depending on provider | Subscription billing, payment processing, and invoicing |
| Authentication providers | Varies by customer configuration | Sign-in and identity verification (including customer-chosen SSO providers) |
Specific providers and processing locations can vary based on customer-selected deployment regions and connected integrations.
A current list of subprocessors is available on request at privacy@relevate.app.
8. International data transfers
Processing locations depend on customer-selected deployment regions and connected integrations.
Some service providers may be located outside the EU/UK, including in the United States. When personal information is transferred internationally, we use appropriate safeguards, including:
- European Commission adequacy decisions, where available
- Standard Contractual Clauses (SCCs)
- UK transfer safeguards where applicable
Where required, we assess transfer risks and apply supplementary technical and organizational measures.
Transfer locations depend on the providers and customer-configured integrations used for a given account.
9. Security
We implement administrative, technical, and organizational safeguards designed to protect personal information, including:
- Encryption in transit using TLS
- Encryption at rest where appropriate
- Access controls and least-privilege permissions
- Security logging, monitoring, and abuse detection
- Incident response and remediation procedures
No method of transmission or storage is completely secure, but we work to continuously improve our safeguards.
Personal data breach notification
Where required by law, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach.
If a breach is likely to result in a high risk to individuals, we will notify affected users without undue delay.
When required, our notice will include available details about the nature of the breach, likely consequences, and mitigation steps, and will be sent to the registered account email address and/or in-product where appropriate.
10. Data retention
We retain personal information only as long as needed for the purposes described in this policy, including legal, accounting, and security requirements.
- Account and profile data: for as long as your account is active
- Security and service logs: typically up to 12 months
- Billing and tax records: typically up to 7 years where required
- Backups: may be retained for up to 90 days before deletion
After account termination, we will make customer data available for export for up to 30 days.
To protect users and prevent unauthorized access, we may require identity verification and provide exports through secure methods.
After the export window, we may delete or anonymize customer data and personal information, except where we must retain it to comply with law (including tax and accounting) or to resolve disputes.
11. Children’s information
Our Services are intended for business users and are not intended for children under the age of 18. We do not knowingly collect personal information from children.
12. Your privacy rights
Depending on your location, you may have rights under applicable data protection laws, including the right to:
- Access your personal information
- Correct inaccurate information
- Request deletion of your information
- Object to or restrict processing
- Request data portability
How to delete your account
- Send a deletion request to privacy@relevate.app from your registered account email address.
- We may verify identity before processing deletion requests.
- After termination, customer data is generally available for export for up to 30 days.
- After the export window, we delete or anonymize data unless retention is required by law or for dispute resolution.
- Backups may persist for up to 90 days before deletion.
To protect your information, we may verify your identity before processing a request (for example, by confirming control of the relevant account email and requesting additional details where needed).
For EEA/UK requests, we generally respond within one month. If a request is complex, we may extend this period as permitted by law and notify you of the reason.
EEA/UK users may exercise applicable data protection rights, including data access and portability, by contacting privacy@relevate.app.
If you are in the EEA or UK, you may also have the right to lodge a complaint with your local data protection authority. If you are located in the Netherlands, you may lodge a complaint with the Dutch supervisory authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl/en.
If you are in a U.S. state with an applicable privacy law, you may have rights to know, access, correct, delete, and obtain a copy of personal data, and to appeal certain privacy request decisions. To appeal, reply to our privacy response email or contact privacy@relevate.app with the subject line "Privacy Appeal."
To exercise your rights, contact us at privacy@relevate.app.
13. Do Not Track signals
Some browsers offer a "Do Not Track" feature. We do not respond to browser Do Not Track signals.
We honor Global Privacy Control as an opt out of sale or sharing where applicable. We do not sell personal information.
14. Updates to this policy
We may update this Privacy Policy from time to time. The updated version will be indicated by the "Last updated" date at the top of this page.
For material updates, we will provide at least 30 days' advance notice (for example by email or in-product notice), except where faster changes are required for legal, regulatory, or security reasons.
15. Contact us
If you have questions or concerns about this Privacy Policy or our data practices, contact us at: